The license also makes it clear that the authors aren't liable for any damages.
The license disclaims liability but that doesn't mean the author cannot ever be held liable. Ultimately, who is liable is up to a court to decide.
You find a vulnerability? patch it, push change to repo maintainer.
https://xkcd.com/2347
Why are you using random, unvetted and unaudited code where safety is important?
They are sharing their knowledge about how to create a tiny JSON parser. Where is the problem again?